Company
Date Published
Author
Paul Davis, Field CISO
Word count
532
Language
English
Hacker News points
None

Summary

A survey of over 1,200 technology professionals, including more than 300 VP and C-level executives, revealed significant discrepancies between executives' perceptions and developers' reports regarding the integration of AI/ML tools and security practices in software supply chains. A substantial gap exists in the perceived integration of AI/ML in security scanning, with 88% of executives and only 60% of developers acknowledging such integration. Similarly, 90% of executives versus 63% of developers claim the use of ML models in software, and 92% of executives compared to 70% of developers believe in the existence of solutions for detecting malicious open-source packages. The study highlights regional variations, with the APAC region leading in perceived integration, followed by the United States. The differences suggest that executives may underestimate the time and effort required for security processes and overestimate the automation of code reviews. This disconnect calls for improved alignment between executives and developers to better address security challenges and optimize AI/ML usage.